Scott You must forgive me my persistence but I will exhaust this until I fully understand what to do.
Your reply makes a lot of sense but a couple of items are still confusing me. I already have the list of ports required by IMAIL and I used these to setup the IP filtering under networking. The system worked fine. We have No NAT and the IMAIL box has its own IP address as does the Firewall etc. The firewall has an option to create additional ports with rules for incoming and outgoing traffic separately. The main point which confuses me is what IP address to use for the imail server? Does it get an internal address or an outside address? Also, do I have to alter my DNS entry if the mail server moves behind the firewall? Regards Stephen Pokora [EMAIL PROTECTED] -----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of R. Scott Perry Sent: 06 February 2004 15:32 To: [EMAIL PROTECTED] Subject: RE: [IMail Forum] The use of a firewall >With regard to placing the imail server behind the existing firewall in >the office what items need addressing? The same items as any other computer behind the firewall that people may need to access. You'll need to set up the firewall to allow access to port 25 on the IMail server, at the very least. You then should open up any other ports that you want outside people accessing (for example, if people may access POP3 outside of your office, you would want to open port 110). If you have strict firewall settings (that prevent you from connecting to unauthorized ports), you may need to enable *outgoing* access to TCP port 25 (SMTP) and TCP/UDP port 53 (DNS). If you're running a Cisco PIX firewall, you need to make sure not to use their broken "SMTP fixup protocol". >Do I have to alter my DNS entry for the imail server so that it when it >resolves the MX records it points to the firewall and then create rules >on the firewall to direct these requests towards the IMAIL box? The MX record should point to the external IP of the IMail server. If the IMail server has its own IP, that's the one to use. If the firewall uses NAT and shares one IP among all computers behind it, that is the one that you would use. If you are using NAT, you would need to create a rule on the firewall so that it knows that incoming packets to port 25 should go to the IMail server. >I really want to use the web messaging and pretty much all the functions >of IMAIL as I have set up IMAIL before and staff thought it was >fantastic to be able to access mail from outside the office. The same >goes here. Can IMAIL operate properly behind the firewall in my >situation? Yes. You just need to let the firewall know of any ports that you want people outside the office to connect to (the ports that may be used are in the URL in my previous post). -Scott --- Declude JunkMail: The advanced anti-spam solution for IMail mailservers since 2000. Declude Virus: Catches known viruses and is the leader in mailserver vulnerability detection. Find out what you've been missing: Ask for a free 30-day evaluation. --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/ To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
